@nurturejs/aws-plugin
v0.3.2
Published
AWS plugin for NurtureJS - read values from the AWS SSM Parameter Store
Maintainers
Readme
AWS Nurture plugin
This plugin is a very simple way of reading AWS SSM parameters and Secrets Manager secrets from Nurture.
Usage
When loading, add a top level aws key indexed by environment to map your environments to profiles and regions. The profile and region key are picked up and intepreted in order ot fetch the values from the correct profile.
This assumes that you have an .aws.config and .aws/credentials set up in your home directory.
Example usage:
{
"aws": {
"dev": {
"region": "us-east-1",
"profile": "aws-dev-profile"
},
"prod": {
"region": "us-east-1",
"profile": "aws-prod-profile"
}
},
"variables": [
{
"name": "AWS_VAR",
"description": "An AWS SSM parameter variable",
"source": "aws",
"parameter": "/path/to/ssm/key"
}
]
}To read from AWS Secrets Manager instead of SSM, give the variable a secret (the secret's name or ARN) instead of a parameter. The secret's string value is used as-is:
"variables": [
{
"name": "AWS_SECRET_VAR",
"description": "An AWS Secrets Manager secret",
"source": "aws",
"secret": "my-app/api-key"
}
]To read a parameter or secret from a region other than the environment's default, set region on the variable. Other variables still use the environment's region:
"variables": [
{
"name": "AWS_EU_VAR",
"description": "An AWS SSM parameter stored in another region",
"source": "aws",
"parameter": "/path/to/ssm/key",
"region": "eu-west-2"
}
]Like parameter, secret and region can also be set inside the variable's aws key (see below), which takes precedence over the top-level field.
If using with mutliple sources, you can use the following syntax to prevent name collision:
"variables": [
{
"name": "AWS_VAR",
"description": "An AWS SSM parameter variable",
"sources": ["environment", "aws"],
"aws": {
"parameter": "/path/to/ssm/key"
}
}
]
}Errors
If a parameter or secret does not exist, the plugin returns no value and says so, so the variable falls through to its next source or its default:
VariableNotSetError: Variable OKTA_TOKEN not set. Tried:
- aws: SSM parameter /identity/okta not found (region eu-west-1, profile dev)Any other AWS error (missing permissions, expired credentials, an unreachable region) is raised with the parameter or secret, region and profile in the message. Nurture catches it, logs it at level 1 and carries on to the variable's next source or its default; if the variable has neither, the run fails with that message.
